Information Technology Security Directive 5-410-1_v3.5_07082020.pdf
PDF 958 KB Posted
- Attached to
- Library of Congress RFI - Electronic Visitor Counting and Analytics System Federal contract opportunity
- Solicitation number
- CIO20210112
- Issued by
- Library of Congress
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| LC Security Assessment and Authorization Guidance_08242020_v5.1.pdf | ||
| Final Responses to Vendor Questions - CIO20210112.pdf | ||
| LIBN_VCSAT_RFI_100720_Requirements_ReportSample.pdf | ||
| Library of Congress RFI - Electronic Visitor Counting System.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
THE LIBRARY OF CONGRESS
WASHINGTON, D.C. 20540
Information Technology Security Directive
5-410.1
General Information Technology Security
TO: Library of Congress Executive Committee (EC) Library of Congress Information Technology Steering Committee (ITSC)
FROM: Bernard A. Barton, Chief Information Officer (CIO), Office of the Chief Information Officer (OCIO)
SUBJECT: General Information Technology Security Directive
EFFECTIVE July 8, 2020
IT Security Directive 5-410.1 July 8, 2020 i i
Revision History Revision Date Revised By Notes
3.5 July 8, 2020 Karen Beirne Added – 5.3.5.r, 5.3.3.s
Modified – 5.1.5.c, 3.12.e Removed – 4.7.b, 3.15.u-1 Removed entire section “Continuity Planning for Critical LC Assets”. Refer to Directive 5-620.1 for these policies.
i i i
Table of Contents
Introduction Information Technology Security Program Authorities Scope Policy Overview Definitions Waivers and Waiver Requests
Waivers Waiver Requests
Changes to Policy Roles and Responsibilities IT Security Program Roles
LC Chief Information Security Officer (CISO) / Senior Agency Information Security Officer Authorizing Official (AO) Information System Business Owner (ISBO) Information Systems Security Officer
Other Roles Library of Congress Chief Information Officer (CIO) Heads of LC Service Units Information Owner/Steward Common Control Provider LC Employees, Contractors, and Others Working on Behalf of LC
ITSEC
Management Policies Basic Requirements Capital P lanning and Investment Control Contractors and Outsourced Operations IT Business Continuity and Disaster Recovery (BCDR) System Development Life Cycle (SDLC) Requirements Definitions Design Development Test Implementation Operations and Maintenance Configuration Management Risk Management Risk Assessment Security Authorization and Security Control Assessments Ongoing Authorization System Security Plan (SP) Security Control Assessment and Security Acceptance Testing Plan of Action and Milestones (POA&Ms) iv
Information Security Policy Violation and Disciplinary Action Required Reporting Privacy and Data Security
Personally Identifiable Information (PII) and Sensitive PII Protecting Privacy Sensitive Systems Privacy Incident Reporting
Social Media Operational Policies Personnel
Citizenship, Personnel Screening, and Position Categorization Rules of Behavior Access to Sensitive Information Separation of Duties Information Security Awareness, Training, and Education Role –Based Training Separation from Duty
Physical Security General Physical Access Physical Access
Media Controls Media Protection Media Marking and Transport Media Sanitization and Disposal Production, Input/Output Controls
Telecommunications Security Data Communications Facsimiles Video Teleconferencing Voice Over Data Networks (VoIP)
Wireless Network Communications Wireless Portable Electronic Devices
Equipment Servers Workstations Laptop Computers and Other Mobile Computing Devices Personally Owned Equipment and Software Hardware and Software Wireless Settings for Peripheral Equipment
IT Security Incidents and Incident Response & Reporting Vulnerability Management Law Enforcement Incident Response
Documentation Converging Technologies Technical Policies Identification and Authentication
Passwords v
Access Control Automatic Account Lockout Automatic Session Termination Warning Banner
Auditing Network and Communications Security
Remote Access and Dial-In Network Security Monitoring Network Connectivity Management of Firewalls and Policy Enforcement Points Internet Security Email Security Testing and Vulnerability Management Peer-to-Peer Technology
Cryptography Encryption
Public/Private Key Malware Protection Product Assurance Questions and Comments Appendix A – Revision History Appendix B – Acronyms Appendix C – Glossary Appendix D – References Appendix E – Allowable IT Security Role Combinations
Introduction This document articulates the Library of Congress (LC) Information Technology (IT) Security Program policies for information systems. This policy serves as a foundation for Library service units to develop and implement their information security programs. The baseline security requirements included in this policy must be addressed when developing and maintaining information security documents.
Information Technology Security Program The LC IT Security Program provides a baseline of policies, procedures, standards, and guidelines for Library service units. This document provides direction to managers and senior executives for managing and protecting information systems. It also outlines policies relating to management, operational, and technical controls necessary for ensuring confidentiality, integrity, and availability within the LC information system infrastructure and operations. Policy elements are designed to be broad in scope. Specific implementation information can often be found in National Institute for Standards and Technology (NIST) publications, such as NIST Special Publication (SP) 800-53, Rev.4, Security and Privacy Controls for Federal Information Systems and Organizations.
This directive applies to any outside organizations, or their representatives, who are granted access to the Library’s IT resources, such as other Federal agencies.
From the date of issuance, all new IT systems must comply with this directive and all existing systems must be brought into compliance as resources permit. Information Technology Security Division (ITSEC) compliance tools will be updated to reflect with these Directives.
Authorities The following list provides references for the LC information security program.
• Library of Congress Regulation (LCR) 5-410 IT Security Policy
• 44 U.S.C. 3551, et seq., Federal Information Security Modernization Act of 2014
• NIST Federal Information Processing Standards (FIPS) 200, Minimum Security Requirements for Federal Information and Information Systems
• NIST Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems
• NIST SP 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems
• NIST SP 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations
• NIST SP 800-60, Volume 1, Rev. 1, Guide for Mapping Types of Information and Information Systems to Security Categories
• NIST SP 800-60, Volume 2, Rev. 1, Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
Scope This directive applies to all LC hardware, software (including operating systems, Commercial off the shelf (COTS) software, and custom-developed applications), media and facilities, as well as to all Library service units, personnel, and contractors.
This directive applies to any outside organizations, or their representatives, who are granted access to the Library’s IT resources, such as other Federal agencies.
From the date of issuance, all new IT systems must comply with this directive and all existing systems must be brought into compliance as resources permit.
Systems in place before the issuance of this directive will be assessed against this directive in all future assessments.
Directives marked Low (L) are required for IT systems with a Security Category of Low.
Directives marked Moderate (M) are required for IT systems with a Security Category of Moderate.
Directives marked High (H) are required for IT systems with a Security Category of High.
Directives within the Management Policies are mandatory for the Library and may not directly apply to individual IT systems.
Policy Overview The purpose of this directive is to protect valuable LC assets including information, hardware, and software and to support the overall mission while improving service to the nation. This directive is in conformance with the law and draws upon Federal guidance as well as industry best practices. The primary goal is to protect the confidentiality, integrity, and availability of business resources and digital assets.
This directive extends LCR 5-410, creating the framework for information security at LC. High-level policy is contained in LCR 5-410. General security directives are found in this document.
LC information security policies delineate the security management structure and foundation to measure progress and compliance. Policies in this document are organized under three areas:
LCR 5-410
IT Security Directive 5-410.1
Service Unit Policy and Procedures
• Management Controls – Focus on managing both the system information security controls and system risk. These controls consist of risk mitigation techniques and concerns normally addressed by management.
• Operational Controls – Focus on mechanisms primarily implemented and executed by people. These controls are designed to improve the security of a particular system, or group of systems, and often rely on management and technical controls.
• Technical Controls – Focus on security controls executed by information systems. These controls provide automated protection from unauthorized access or misuse. They facilitate detection of security violations and support security requirements for applications and data.
This IT Security Directive is designed to provide a comprehensive listing of IT security controls that should be implemented within a system’s boundary to protect its information. Within the Management, Operational, and Technical controls section, specific policies are grouped into security categories. Each category lists specific security controls to be implemented for that category. Each policy includes the following –
• Policy ID – A unique ID used track the policy through multiple documents
• LC Policy Statements – The specific IT Security policy to be implemented
• Category – Lists the security categorization to which the policy is applied
• Relevant Controls – Provides the related NIST SP 800-53 Rev 4 security control(s) the LC IT Security policy satisfies.
Privacy controls have been added to LCD 5-410.1 to comply with the publication of NIST SP 800-53, Rev. 4, Appendix J : Privacy Control Catalog. The privacy controls focus on information privacy as a value distinct from, but highly interrelated with, information security.
Privacy controls are administrative, technical, and physical safeguards employed within organization to protect and ensure the proper handling of Personally Identifiable Information
(PII).
Definitions Definitions for all terms used throughout this LCD are documented within Appendix C - Glossary.
Waivers and Waiver Requests Waivers
Library service units may request waivers to any portion of this policy, for up to one (1) year, any time they are unable to fully comply with policy requirements. Requests are made through the Library service unit’s ISSO for the system to the Designated Signing Official (DSO). The DSO is generally the Information System Business Owner (ISBO) for a system, but could also be the Contracting Officer’s Representative (COR) in regards to Virtual Private Network (VPN) Waivers. After the DSO approves the waivers, it is sent to the LC Chief Information Security Officer (CISO) for final review and approval. In all cases waivers shall be requested for an appropriate period of time, no longer than one year, based on a reasonable remediation strategy.
Waiver Requests
All waiver requests are documented within OCIO ITSEC’s Archer Governance, Risk, and Compliance (GRC) tool. Refer to the waiver procedures on how to complete a waiver within Archer.
Waiver requests shall include the operational justification (document mission impact), risk acceptance, risk mitigation measures, and, if applicable, a Plan of Action and Milestones (POA&M) for bringing the system procedures or control weakness into compliance.
Policy ID LC Policy Statements Category Relevant
Controls
1.6.2.a This Security Directive applies to all LC employees, contractors, detailees, others working on behalf of LC, and users of LC information systems that collect, generate, process, store, display, transmit, or receive LC data unless an approved waiver or exception has been granted. This includes prototypes, telecommunications systems, and all systems in all phases of the System Development Life Cycle (SDLC).
L/M/H SA-3
1.6.2.b Systems without an Authorization to Operate (ATO) when this policy is issued shall comply with all of its policy statements or obtain appropriate waivers.
L/M/H PL-1
1.6.2.c Each system waiver request shall include the system name, the directive(s) being waived, the business requirement for the waiver, and an associated POA&M.
L/M/H CM-3
1.6.2.d Service unit system representatives (i.e., Information System Business Owner, Contracting Officer Representatives) shall request a waiver whenever they are temporarily unable to comply fully with any portion of these directives.
L/M/H CA-2
1.6.2.e All system-level waiver requests shall identify the POA&M for bringing the system into compliance.
L/M/H CA-5, PM-4
1.6.2.f A waiver shall be issued for one (1) year or less. Waivers may be renewed once, by following the same process as in the initial request.
L/M/H CA-2
Changes to Policy The policies outlined in this publication serve as a foundation for service units to use in developing and implementing their information security programs and IT systems.
For interpretation or clarification of LC information security policies, procedures, and guidance found in this directive, contact the LC CISO at itsec@loc.gov.
http://www.loc.gov/staff/security/docs/Archer%20Waiver%20Procedure_v2.0_08172018.pdf mailto:%20itsec@loc.gov
Policy ID LC Policy Statements Category Relevant
Controls
1.7.a The LC CISO shall be the authority for interpretation, clarification, and modification of Directive 5-410.1 – General IT Security Directive (inclusive of all appendices and attachments).
L/M/H PL-1
1.7.b The LC CISO shall review annually and update, as necessary, Directive 5-410.1.
L/M/H PL-1
Roles and Responsibilities The LC regards certain IT security roles as inherently governmental. These roles include the LC Chief Information Officer (CIO), LC CISO, Authorizing Officials, Information Owners/Stewards, and Information System Business Owners. Contractors, who are working on behalf of LC, and other sources may assist in the performance of security functions, but an LC employee must always be designated as the responsible agent for all security requirements and functions other than that of the Information System Security Officer (ISSO). This section outlines the roles and responsibilities for implementing these requirements. See also NIST SP 800-37 Revision 1, Guide to Applying the Risk Management Framework (RMF) to Federal Information Systems.
IT Security Program Roles Designated personnel play a major role in the planning and implementation of information security requirements. Roles directly responsible for information system security are described in the following subsections. Certain IT security roles may be combined into a single individual pursuant to the limitations shown in Appendix D – Allowable IT Security Role Combinations.
LC Chief Information Security Officer (CISO) / Senior Agency Information Security Officer
The LC Chief Information Security Officer (CISO) shall implement and manage the LC IT Security Program, ensuring compliance with applicable Federal laws, directives, policies, and regulations. The LC CISO reports directly to the Deputy, Chief Information Officer (CIO) within the Office of the Chief Information Officer. The LC CISO is the principal advisor for all IT security matters. The LC CISO also serves as the Group Leader of ITSEC.
The CISO, or designate, serves as the Security Control Assessor (SCA). The Security Control Assessor (SCA) certifies the results of the security control assessment. The SCA and the team conducting the security assessment must be impartial, that is, free from any perceived or actual conflicts of interest with respect to the developmental, operational, and/or management chain of command associated with the information system or to the determination of security control effectiveness.
Controls
2.1.1.a The LC CISO shall perform the duties and responsibilities of the LC Senior Agency Information Security Officer.
L/M/H
PL-1, PM-
2.1.1.b The LC CISO shall implement and manage the LC IT Security Program.
L/M/H PL-1, PM-
2.1.1.c The LC CISO shall be a dedicated duty, without non-IT security-related collateral duties.
L/M/H PM-2
Controls
2.1.1.d The LC CISO shall not serve as the AO, ISSO, Information System Business Owner (ISBO), Information Owner/Steward (IO), or System Administrator (SA) for any IT system.
L/M/H PM-2
2.1.1.e The LC CISO shall develop an LC IT Security Program Plan for the approval of the CIO.
L/M/H PM-2
2.1.1.f The LC CISO shall assist the CIO, in implementing an LC IT Security Program Plan.
L/M/H PM-2
2.1.1.g The LC CISO shall conduct security compliance reviews to assess the overall effectiveness of security program implementation across LC.
L/M/H PM-2
2.1.1.h The LC CISO shall assess service unit compliance with the LC IT Security Plan.
L/M/H PM-2
2.1.4.a An SCA may be responsible for more than one system. L/M/H CA-2
2.1.4.b The SCA provides an assessment of the severity of weaknesses or deficiencies in the information systems, and prepares the final security control assessment report containing the results and findings from the assessment but not making a risk determination.
L/M/H CA-7
2.2.3.b The CISO shall ensure that an ISSO is designated in writing for each information system.
L/M/H PL-1
The LC CISO:
• Implements and manages the Library of Congress Information Security Program.
• Issues Library-wide information security policy, guidance, and security architecture requirements for all LC systems and networks. These policies shall incorporate NIST guidance.
• Facilitates development of subordinate plans for providing adequate IT security for networks, facilities, and systems or groups of information systems.
• Serves as the principal Library liaison with organizations outside the LC for matters relating to IT security.
• Reviews and approves the tools, techniques, and methodologies planned for use in assessing and authorizing LC systems. This includes, but is not limited to, Security Control Assessment plans and security risk assessments.
• Consults with the director of security, Office of Security & Emergency Preparedness (OSEP), on matters pertaining to physical security, personnel security, and investigations, as they relate to information security and infrastructure.
• Develops and implements procedures for detecting, reporting, and responding to information security incidents.
• Ensures preparation and maintenance of plans and procedures to provide continuity of operations for information systems.
• Set standards for Library personnel, contractors, and others working on behalf of LC to ensure they receive appropriate information security awareness training.
• Maintains a comprehensive IT system’s inventory of all GSS, MA, Minor Applications, Subsystems, and Low Impact Externally Hosted system maintained by Library.
• Maintains a repository for all security assessment and authorization process documentation and modifications.
• Provides oversight of all IT Security operations functions within the Library.
• Performs periodic compliance reviews for selected systems and applications.
• Reports annually to the Librarian of Congress on the effectiveness of the LC IT Security Program, including progress of remedial actions.
• Heads an office with the mission and resources to assist in ensuring Library compliance with information security requirements.
• Provides operational direction to the Library of Congress Security Operations Center
(LC-SOC).
Authorizing Official (AO)
The Authorizing Official (AO) formally assumes responsibility for operating an information system at an acceptable level of risk. The D/CIO shall serve as the Authorizing Official for all LC systems. In the event that a conflict of interest is perceived or apparent, the CIO will assign an alternate AO for a single system.
Policy ID LC Policy Statements Category Relevant
Controls
2.1.3.a The CIO shall assign one AO for each LC IT system and must be appointed in writing.
L/M/H CA-6
2.1.3.b The AO must be a Library employee with sufficient authority to accept risk on behalf of the organization and direct resources to mitigate vulnerabilities posing excessive risk.
L/M/H CA-6
Controls
2.1.3.c Every system shall have a designated AO. An AO may be responsible for more than one system.
L/M/H CA-6
2.1.3.d The AO shall be responsible for acceptance of resulting risk to organizational operations and assets, individuals, other organizations, and the Library.
L/M/H CA-6
2.1.3.e The AO shall periodically review security status to determine if risk remains acceptable.
L/M/H CA-6
2.1.3.f AOs must evaluate security authorization findings and assess vulnerabilities and residual risks.
L/M/H CA-6
2.1.3.g AOs must not also serve as the ISBO, SCA, CISO, ISSO, or SA for any IT system.
Information System Business Owner (ISBO)
Information System Business Owners (ISBO) are responsible for the successful operation of the information systems and programs within their purview and are ultimately accountable for their security. All systems require an ISBO designated in writing for proper administration of security. ISBOs must have regular communication with their ISSOs regarding IT security matters, including POA&M status and other IT security related continuous monitoring activities.
Policy ID LC Policy Statements Category Relevant Controls
2.2.3.a ISBOs shall ensure that each of their systems is deployed and operated in accordance with this policy document.
L/M/H PL-1
2.2.3.c There shall be only one ISBO designated for each LC system. L/M/H PL-1
2.2.3.d All IT systems must have an ISBO responsible for overall management of the IT system appointed in writing by the AO.
L/M/H PL-1
2.2.3.e The ISBO or designate must formally approve all changes to the IT system.
L/M/H CM-3
2.2.3.f The ISBO must ensure that all changes to the IT system, including software and hardware changes, follow a formal change management process.
L/M/H CM-3
Policy ID LC Policy Statements Category Relevant Controls
2.2.3.g The ISBO must ensure that an analysis is performed to determine all necessary training, for both technical and user communities, whenever there is a change in the IT system.
L/M/H CM-3
2.2.3.i The ISBO must be a supervisor within the Library of Congress, with sufficient authority to ensure that the IT system is operated in compliance with LCR 5-410 and the IT Security directives.
L/M/H PS-2
2.2.3.k The ISBO must not serve as the AO, CISO, SCA, ISSO or SA for any IT system.
L/M/H PS-2
2.2.3.n The ISBO must ensure that all access agreements, including records of account management and access authorization, non-disclosure agreements, and Rules of Behavior for Privileged Use agreements are completed as necessary and records are maintained.
L/M/H PS-5
2.2.3.o The ISBO shall document the Security Categorization for the information system, with assistance as needed from the Information Owner/Steward, as applicable. Guidance and direction for conducting a Security Categorization is provided in the NIST SP 800-60, Rev 1, Vol. 1 & 2. Specific information types are listed in Volume 2.
L/M/H RA-2
2.1.2.j ISBOs shall prioritize security weaknesses for mitigation. L/M/H CA-5
Information Systems Security Officer
An Information Systems Security Officer (ISSO) performs designated security actions for an information system. While the ISSO performs security functions, the Information System Business Owner is always responsible for information system security.
Policy ID LC Policy Statements Category Relevant
Controls
2.1.5.a An ISSO shall be designated for every information system and serve as the point of contact for all security matters related to that system.
L/M/H PL-1
2.1.5.b An ISSO shall ensure the implementation and maintenance of security controls in accordance with the system’s Security Plan (SP) and LC policies.
L/M/H PL-1
Controls
2.1.5.c An ISSO may be a LC employee or a contractor. L/M/H PL-1
2.1.5.d An ISSO may be assigned to more than one system. L/M/H PL-1
2.1.5.e ISSOs must be appointed in writing by the CISO. L/M/H PL-1
2.1.5.f ISSOs must respond to IT security-related requests from the ITSEC on information regarding their assigned systems.
L/M/H PL-1
2.1.5.g Each IT system must have at least one primary and one backup ISSO designated.
L/M/H PL-1
2.1.5.h The ISSO must review the audit logs of all remote maintenance sessions.
L/M/H MA-4
2.1.5.i ISSOs may not serve as the AO, CISO, ISBO, IO, SCA, or SA for any IT system.
L/M/H PS-2
2.1.5.j ISSOs must maintain effective communications with the AO, ISBO, IO and SAs.
L/M/H SA-3
2.1.5.k ISSOs receive notice of separations of Library staff via the Terminators email list. This information must be used to validate that accounts and access are removed from their systems within the timeframe prescribed in Separation from Duty and also communicated to their ISBOs.
L/M/H PS-4
2.1.2.k ISSOs shall provide copies of POA&Ms to affected Information System Business Owners.
L/M/H CA-5,
PM-4
2.1.2.l ISSOs shall ensure that POA&Ms address the following:
• The specific weaknesses or deficiencies in the information system security controls
• Appropriate milestones to track mitigation of the weakness
• Timeframe for mitigating the weakness are in line with the POA&M remediation policy.
L/M/H CA-5,
PM-4
2.1.2.m ISSOs shall periodically test the security controls of implemented systems in line with the LC’s Continuous Monitoring guidance.
Information System Security Officers (ISSO) also –
• Acknowledge receipt of Security Advisory messages, report compliance with requirements, or notify ITSEC to grant a waiver.
• Ensure system adheres to the LC Secure Baseline Configuration Guides. These can be found at http://www.loc.gov/staff/security/hardening-guides.html
• Implement Library information security policies, procedures, and control techniques to address all applicable requirements.
• Ensure training and oversight for personnel with significant responsibilities for information security.
Other Roles Roles related to, but not directly responsible for, information system security is described in the following subsections.
Library of Congress Chief Information Officer (CIO)
The person filling this role is responsible for ensuring that the Library’s IT Security Program is established and managed in accordance with LC policy and directives.
The LC CIO serves as the LC Risk Executive ensuring that risks are managed consistently across the organization. The Risk Executive provides a holistic view of risk beyond that associated with the operation and use of individual information systems.
Risk Executive inputs are documented and become part of the security Assessment and Authorization decision. The LC Risk Executive:
• Ensures that managing information system-related security risks is consistent across the organization, reflects organizational risk tolerance, and is performed as part of an organization-wide process that considers other organizational risks affecting mission/business success.
• Ensures that information security considerations for individual information systems, including the specific authorization decisions for those systems, are viewed from an organization-wide perspective with regard to the overall strategic goals and objectives of the organization.
• Provides visibility into the decisions of the AO and a holistic view of risk to the organization beyond the risk associated with the operation and use of individual information systems.
• Facilitates the sharing of security-related and risk-related information among the AO and other senior leaders within the organization in order to help these officials consider all types of risks that may affect mission and business success and the overall interests of the organization at large.
2.1.1.j The LC CIO shall act as the LC Risk Executive. L/M/H PL-1, PM-
Heads of LC Service Units
The heads of LC service units are responsible for oversight of the service unit information security program. Persons filling this role allocate adequate resources to information systems for information system security.
2.2.2.a The Heads of service units shall ensure that information systems and their data are sufficiently protected.
PL-1
2.2.2.b Ensure that adequate funding for information security is provided for service unit information systems and that adequate funding requirements are included for all information systems budgets.
L/M/H SA-2
Heads of LC service units:
• Ensure that the security of information systems is an integral part of the life cycle management process for all information systems developed and maintained within their service units
• Ensure that adequate funding for information security is provided for service unit information systems and that adequate funding requirements are included for all information systems budgets
• Ensure that information system data is entered into the appropriate LC Security Management Tools to support LC information security oversight
• Ensure that the requirements for an information security performance metrics program are implemented and the resulting data maintained and reported.
Information Owner/Steward
The information owner/steward is an organizational official with statutory, management, or operational authority for specified information and the responsibility for establishing the policies and procedures governing its generation, collection, processing, dissemination, and disposal.
The owner/steward of the information processed, stored, or transmitted by an information system may or may not be the same as the system owner.
Policy ID LC Policy Statements Category Relevant Controls
2.2.4.a The IO of information owned by the Library of Congress must be a Library of Congress employee with sufficient authority to determine the impact on the Library's mission due to compromise of the information.
L/M/H PS-2
2.2.4.b The IO must not serve as the CISO, SCA, ISSO or SA for any IT System.
L/M/H PS-2
Common Control Provider
The Common Control Provider is an organizational official responsible for planning, development, implementation, assessment, authorization, and maintenance of organization common controls.
Policy ID LC Policy Statements Category Relevant Controls
2.2.5.a The Common Control Provider shall document all LC common controls and submit them to the AO.
PM-1
2.2.5.b The LC CISO, on behalf of the Common Control Provider ensures that required assessments of common controls are carried out by qualified assessors with the appropriate level of independence.
2.2.5.c The Common Control Provider documents assessment findings in a security assessment report (SAR).
2.2.5.d The Common Control Provider ensures that POA&Ms are developed for all controls having weaknesses or deficiencies.
2.2.5.e The Common Control Provider shall make available security plans, SARs, and POA&Ms for common controls to Information System Business Owners inheriting those controls after the information is reviewed and approved by a senior official.
PM-1,
PM-4
LC Employees, Contractors, and Others Working on Behalf of LC
LC employees, contractors, and others working on behalf of the LC or its service units shall follow the appropriate set(s) of rules of behavior.
Policy ID LC Policy Statements Category Relevant Controls
2.2.6.a LC users shall follow prescribed rules of behavior and be held responsible for their actions on IT systems.
PL-4, PS-
6, PS-8
ITSEC
ITSEC ensures that IT systems and IT systems security staff are complying with established IT security policy and guidance. Staff within this group will ensure that the service unit head and LC CISO are kept apprised of all pertinent matters involving the security of information systems. They will also ensure that IT security-related decisions and information, including updates to this directive, are distributed to the ISSOs and other appropriate persons. ITSEC is responsible for implementing and managing the POA&M process for the LC and review remediated POA&M for closure.
Policy ID LC Policy Statements Category Relevant Controls
2.1.2.i ITSEC shall ensure that program POA&Ms are prepared and maintained.
L/M/H CA-5, PM-
2.1.6.a ITSEC shall serve as the point of contact for all ongoing risk management activities for systems enrolled into the OA Program.
L/M/H PL-1
2.1.6.c ITSEC shall ensure that timely analysis of identified security events are provided to the AO to determine security risk.
L/M/H ---
2.1.6.e ITSEC shall be responsible for tracking security events, recording recommendations, and ensuring at least quarterly communication with the AO on system risks.
L/M/H ---
3.15.a-1 ITSEC must ensure that an approval process exists for all accreditation packages.
Management Policies
Basic Requirements Basic security management principles must be followed in order to ensure the security of LC information resources. These principles are applicable throughout the Library and form the cornerstone of the LC IT Security Program.
Policy ID LC Policy Statements Category Relevant Controls
3.1.a Every LC computing resource is identified as an information system or as a part of an information system (Major Application or General Support System). This identification must include a defined system inventory of all IT system components within the authorization boundary, appropriate to the granularity deemed necessary for tracking and reporting.
L/M/H CM-8
3.1.c The IT system must employ automated mechanisms to highlight proposed changes to the information system that have not been approved or disapproved by 48 hours.
H CM-3
3.1.d The IT system must employ automated mechanisms to prohibit the change until necessary approvals are received.
H CM-3
3.1.e The IT system must employ automated mechanisms to document completed changes to the information system.
H CM-3
3.1.f Internet Service Provider (ISP) costs related to mobile computing used for activities, such as telework and Bring- Your-Own-Device (BYOD), must be paid for by the staff member and are not reimbursable by the Library
M/H ---
3.1.g OCIO is the sole manager of IP addresses on the LCDN, including managing Dynamic Host Configuration Protocol (DHCP) servers and allocating static IP addresses to servers.
L/M/H CM-3
3.1.h Devices attached to the LCDN with multiple interfaces must not transmit packets between their interfaces with the exception of routers, switches, firewalls, and boundary devices specified by OCIO.
L/M/H AC-4, CA-
3.1.i Each position of system responsibility must be reviewed and classified in terms of its sensitivity in accordance with LCR 9-220.
L/M/H PS-2
3.1.j OCIO, with the Office of the General Counsel (OGC) and the Office of Contracts and Grants Management (OCGM), L/M/H SA-1 will annually review and update if necessary, the services acquisition policy with regard to IT security, and disseminate to Library of Congress staff.
3.1.k All boundary devices separating LC resources from non-LC resources shall be managed by OCIO.
L/M/H SC-7
3.1.l On an annual basis, OCIO shall review the system and information integrity policy and procedures, updating as necessary, and disseminate to Library of Congress staff.
L/M/H SI-1
3.1.m Periodic job/shift rotations must occur for employees in positions of significant security sensitivity (e.g., Systems Administrators, database administrators, account management). Note that this is not a requirement for regular end users of IT systems.
M/H ---
3.1.n Regularly scheduled vacations must occur for employees in positions of significant security sensitivity (e.g., Systems Administrators, database administrators, account management), during which another individual must perform the vacationing employee’s job responsibilities.
Note that this is not a requirement for regular end users of IT systems.
M/H ---
3.1.o Documented IT system-related job descriptions must accurately reflect assigned duties and responsibilities that segregate duties.
M/H ---
3.1.p IT responsibilities must be assigned to staff using the principle of least privilege.
M/H ---
3.1.q OCIO and OCGM will jointly issue the services acquisition policy with regard to IT security.
L/M/H ---
3.1.r OCGM will include the IT security requirements as documented in the services acquisition policy with regard to IT security in all solicitations.
L/M/H ---
3.1.s OCIO will approve changes to solicitations with regard to IT security on a case by case basis.
L/M/H ---
3.1.t OCIO will notify service units when significant modifications to boundary protection devices that have the potential of significantly altering the security level or hindering the mission of the service units.
L/M/H ---
3.1.u All data centers must be approved by OCIO. L/M/H ---
3.1.v All security controls must be consistent with and an integral part of the IT Enterprise Architecture (EA) of the Library.
L/M/H ---
3.1.w Security controls must be commensurate with NIST SP 800- 53 Rev.4, Security and Privacy Controls for Federal Information Systems and Organizations per the information Security Categorization of the system.
L/M/H PL-2
3.1.x The LC IT Security Program must conduct an annual review of the Library’s IT system inventory in line with the LC’s Inventory Management Program.
L/M/H PM-5
Capital Planning and Investment Control Information security is a business driver and any risks found through security testing are ultimately business risks. Information security personnel should be involved, to the maximum extent possible, in all aspects of the acquisition process.
Policy ID LC Policy Statements Category Relevant Controls
3.2.a The ISBO shall plan for and provide IT Security protection by budgeting adequate resources to fulfill all LC security requirements throughout the entire lifetime of the system.
L/M/H SA-2
3.2.b Information System Business Owners, and AOs, shall ensure that information security requirements and POA&Ms are adequately funded, resourced, and documented.
L/M/H PM-3,
PM-4,
SA-2
3.2.c Service units shall ensure that information security requirements, as described within this directive, are included in the acquisition of all LC systems used to input, process, store, display, or transmit LC information.
L/M/H SA-4
Contractors and Outsourced Operations
Controls
3.3.a All statements of work and contract vehicles shall identify and document the specific security requirements for information system services and operations required of the contractor.
L/M/H SA-4
3.3.b Contractor information system services and operations shall adhere to all applicable LC information security LCRs and directives.
L/M/H SA-9
3.3.c Statements of work and contracts shall include a provision stating that, upon the end of the contract, the contractor shall return all information and information resources provided during the life of the contract and certify that all LC information has been purged from any contractor-owned system used to process LC information.
L/M/H SA-4
IT Business Continuity and Disaster Recovery (BCDR) All policies associated with IT Business Continuity and Disaster Recovery, to include Continuity of Operations Planning and Contingency Planning and Testing, are included within the Directive 5-620.1. Please refer to Directive 5-620.1 for specific policies on IT Business Continuity and Disaster Recovery.
System Development Life Cycle (SDLC)
Policy ID LC Policy Statements Category Relevant
Controls
3.5.a ISBOs shall ensure that system security is integrated into all phases of SDLC.
L/M/H SA-3
3.5.b ISBOs shall ensure that security requirements for sensitive information systems are incorporated into SDLC documentation.
L/M/H SA-3
3.5.c The AO, SCA, ISBO, and IO must be assigned during the initiation phase.
L/M/H SA-3
3.5.d System interconnections must be determined during the initiation phase.
L/M/H SA-3
3.5.e Applications hosted by OCIO must conform to the OCIO SDLC process.
L/M/H SA-3
https://staff.loc.gov/sites/rules-and-regulations/regulation/lcd-5-620-1/ https://staff.loc.gov/sites/rules-and-regulations/regulation/lcd-5-620-1/
Requirements Definitions
ID LC Policy Statements Category Relevant
Controls
3.6.a The IT system must mark all output with the Security Category of the IT system. (e.g., “Security Category: High” should be displayed in the footer).
H MP-3
3.6.b Standard Operating Procedures (SOPs) must be developed for all IT systems and documented in electronic format. All SOPs must be readily available via electronic means to personnel authorized by the ISBO or designee.
L/M/H MA-2
3.6.c All SOPs must be reviewed on an annual basis and updated if necessary.
L/M/H MA-2
3.6.d Before a new information system is deployed into the production environment, SOPs must be developed and tested in LOCTest.
L/M/H MA-2
3.6.e The Service Unit must determine the adequacy of security requirements, extending LCR 5-410 and the IT Security Directives by documenting any system specific requirements.
L/M/H SA-3
3.6.f The system’s SP must be completed during the development/ acquisition phase.
L/M/H SA-3
3.6.g IT systems must include all applicable IT Security Directives (as determined by ITSEC) in the system requirements.
L/M/H SA-8
3.6.h Systems utilizing web browser interfaces must utilize at least a 2,048-bit key size to create the digital certificate used to provide transport layer security (TLS).
L/M/H SC-13
Design
ID LC Policy Statements Category Relevant
Controls
3.7.a All security controls must be designed or acquired during the development/acquisition phase.
L/M/H SA-3
3.7.b All IT systems must physically and/or logically separate user interface services (e.g., public web pages) from information storage and management services (e.g., database management).
M/H SC-2, SC-
Controls
3.7.c The IT system must isolate security functions from non-security functions.
H SC-3
3.7.d All IT systems must prevent unauthorized and unintended information transfer via shared system resources.
M/H SC-4
3.7.e Client web browsers must only have session cookies enabled and static (first party or long term) cookies disabled.
M/H SC-4
3.7.f The use of third party cookies (cookies that communicate to a server other than originating server) must be disabled on web browsers.
M/H SC-4
3.7.g Protocols that expose authentication information in clear text must not be utilized.
M/H SC-8
3.7.h Servers directly accessible from the Internet must only contain read-only, static information (e.g., HTML files, scripts) and information required to support the operation of the server.
L/M/H AC-2, AC-
3, AC-5,
AC-6, SI-
3, SI-4, SI-
5, SI-7, SI-
Development
ID LC Policy Statements Category Relevant
Controls
3.8.a All Memorandum of Understanding (MOUs) must be developed and signed by the AO during the development/acquisition phase.
L/M/H SA-3
3.8.b All development and integration must be performed on equipment configured with the relevant LC Secure Baseline Configuration Guide(s).
L/M/H SA-8
3.8.c The developer must provide documented evidence to the ISBO upon request that proves that configuration management plan was utilized during all development activities.
H SA-10
Test
ID LC Policy Statements Category Relevant
Controls
3.9.a All new software packages, upgrades, COTS products, or custom software must be inspected and tested before being introduced into the production environment.
L/M/H CM-3
3.9.b Production data with a Security Category confidentiality value of Moderate or High must never be stored or utilized on test systems.
M/H SA-8
3.9.c Production data utilized for testing must never be moved back into the production environment.
L/M/H SA-8
3.9.d Test systems must visually indicate they are test systems in all user and administrative interfaces (e.g., special prompts, backgrounds, etc.).
L/M/H SA-8
3.9.e External service providers must show documented test results showing that the applications, hosting platforms, and associated management systems supporting LC IT systems have implemented the minimum security controls per NIST SP 800-53 (management, operational, and technical) associated with the Security Categorization of the system.
L/M/H SA-9
3.9.f All components of IT systems, whether COTS, internally developed, developed under contract or open source, must undergo Security Control Assessment as part of the security Assessment and Authorization process.
M/H SA-11
Implementation
ID LC Policy Statements Category Relevant
3.10.a All data centers must have an assigned Data Center Manager. H PE-18
Operations and Maintenance
ID LC Policy Statements Category Relevant
Controls
3.11.a The ISBO must ensure that all IT system maintenance procedures are adequate and are reviewed and updated, as
L/M/H MA-1
Controls necessary, on an annual basis, and disseminated to system stakeholders.
3.11.b On an annual basis, OCIO will review the system maintenance policy, updating as necessary, and disseminate to Library of Congress staff.
L/M/H MA-2
3.11.c A schedule for routine preventive maintenance for all IT system elements must be documented in accordance with manufacturer or vendor specifications and/or organizational requirements.
L/M/H MA-2
3.11.d Routine system maintenance must be performed according to the documented schedule and in accordance with manufacturer or vendor specifications and/or organizational requirements.
L/M/H MA-2
3.11.e Records of routine system maintenance must be maintained in accordance with manufacturer or vendor specifications and/or organizational requirements.
L/M/H MA-2
3.11.f After maintenance is performed on the IT system, all potentially impacted security controls must be checked to verify that the controls are still functioning properly.
L/M/H MA-2
3.11.g Maintenance procedures must account for the onsite maintenance of systems.
L/M/H MA-2
3.11.h Maintenance procedures must account for maintenance via remote communications connections, where appropriate.
L/M/H MA-2
3.11.i Maintenance procedures must account for offsite maintenance of systems, where appropriate.
L/M/H MA-2
3.11.j Maintenance records for the IT system must include: (i) the date and time of maintenance; (ii) name of the individual performing the maintenance; (iii) name of escort, if necessary;
(iv) a description of the maintenance performed; and (v) a list of equipment removed or replaced (including identification numbers, if applicable).
L/M/H MA-2
3.11.k The IT system must employ automated mechanisms to schedule and conduct maintenance as required and to create up-to-date, accurate, complete, and available records of all maintenance actions, both needed and completed.
L/M/H MA-2
Controls
3.11.l The ISBO must ensure that all maintenance tools carried into a facility by maintenance personnel are inspected for obvious improper modifications.
M/H MA-3
3.11.m The ISBO must ensure that all maintenance equipment with the capability of retaining information is checked to ensure that no organizational information is written on the equipment or the equipment is appropriately sanitized before release.
M/H MA-3
3.11.n The ISBO must ensure that equipment which cannot be sanitized remains within the facility or is destroyed, unless an appropriate organization official explicitly authorizes an exception.
M/H MA-3
3.11.o Access agreements allowing remote maintenance must expire at the end of the period of performance for the contract or in one year, whichever is sooner.
L/M/H MA-4
3.11.p The ISBO must ensure that remote maintenance or diagnostic services are performed by a provider that implements for its own information system a level of security at least as high as that implemented on the system being serviced, unless the component being serviced is removed from the information system.
H MA-4
3.11.q The ISBO must ensure that any component that is removed from the IT system for servicing is sanitized (with regard to organizational information) before the service begins and also sanitized (with regard to potentially malicious software) after the service is performed, and before being reconnected to the information system.
H MA-4
3.11.r The ISBO must ensure that a documented list of personnel or organizations authorized to perform maintenance on the IT system is maintained.
L/M/H MA-5
3.11.s The ISBO must ensure maintenance is only performed by individuals or organizations on the authorized maintenance personnel list.
L/M/H MA-5
3.11.t All service units must maintain hardware and software maintenance contracts for all hardware and software owned and managed by that service unit.
L/M/H MA-6, PL-
3.11.u The ISBO must ensure that maintenance support agreements are in place for all components of the IT system to permit the
M/H MA-6
Controls resumption of IT system operations within the allowable outage time determined in the BIA.
3.11.v The ISBO must ensure that spare parts for all components of the IT system are available to permit the resumption of IT system operations within the allowable outage time determined in the BIA.
M/H MA-6
3.11.w The ISBO must ensure that an identified custodian is utilized at all times to transport IT system media (USB, tape, etc.)
outside of the facility where the system is located.
M/H MP-5
3.11.x The system must be managed according to the security controls documented in the system’s SP.
L/M/H SA-3
3.11.y The IT system must verify the correct operation of security functions upon system startup and/or restart. When anomalies are discovered, the system must notify the SA and shut down or restart.
H SI-6
3.11.z SOPs should contain at a minimum:
• Source and procedures for patching and restoration.
• Source and procedures for installation or removal.
• Summary of Auditable Processes for Ongoing, Semiannual, and Annual requirements.
• Key contacts and assignments.
• Description of user authorization process and body of evidence.
• Description of regular account reviews, with particular emphasis on any privileged users.
• Description and sampling of any audit reports to be produced.
• Basic outline…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .